Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

121–130 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#121

Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

As someone who lives in Texas, I can confirm that Texas is a one-party state. I specifically do not need to inform people of recording devices if I am a party to the conversation.

It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring.

Re: What Happens When You Send a Zero-Day to a Bank?

#122
post #101

Earlier quoted context omitted.

Consideration can be as minimal as "your continued employment with this company." It does not have to be any sort of additional dollar amount.

"We won't sue you", however, is not consideration.

I wouldn't be so sure - for example, out of court settlements pretty much amount to "We'll pay you $x without admitting that we ever did something wrong, and you agree not to sue us over that thing that we totally did not do.", and these definitely are valid contracts.

Re: What Happens When You Send a Zero-Day to a Bank?

#123
post #86

Earlier quoted context omitted.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…

Suppose they granted your plan to "cancel the credit card accounts" and "potential fraud source" note on each account. That's pretty much trying to shut down business with their customers. You don't see how they'd interpret that as hostile? Future actors would know how to apply similar techniques if the outcome was in their favor (e.g. Anonymous suddenly produces a large file of cc#'s and threatens bank!) > The only…

When you come across a single credit card number (say, by finding someone's card on the ground), the response by most financial institutions is to invalidate that card and mail them a new one. Why shouldn't the response be the same if you come across a stack of 100 credit cards?

Re: What Happens When You Send a Zero-Day to a Bank?

#124

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

> let the market do what she does best: work.

Hm, I recall the Comodo hack. I think it Comodo was hacked twice or more times that year. It won many rewards and continued leading the CA space. The market did not work apparently...

Re: What Happens When You Send a Zero-Day to a Bank?

#125
post #55

Earlier quoted context omitted.

Couldn't anyone who lost money on a stock be able to claim damages? How would the bank prove the purchase order was legitimate seeing as there's basically no security around the endpoint and the bank knew it?

The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.

The article covers this:

>Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.

Re: What Happens When You Send a Zero-Day to a Bank?

#126
post #46

Earlier quoted context omitted.

No. But I can read.

Are you a heart surgeon? No but I can read. I'll stick to advice from subject matter experts, not self appointed experts.

Lawyers tend not to tell they are on internet because of potential liability. Thus when you read IANAL odds are goods that the writer known about the subject but don't want to be liable in any way so he just protect itself.

PS: and if you want an advice by a lawyer that accept liabilities for its counsel just pay for it, because that is the only way you get it.

Re: What Happens When You Send a Zero-Day to a Bank?

#127
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

Agreed, that was the first thing I thought when I looked through it. It's a totally one-sided contract, which is invalid for that reason.

Re: What Happens When You Send a Zero-Day to a Bank?

#128

Earlier quoted context omitted.

Maybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.

Is it proven anywhere that it wasn't?

The article mentions that unauthorized transactions were indistinguishable from legit ones:

>Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.

Re: What Happens When You Send a Zero-Day to a Bank?

#129
post #86

Earlier quoted context omitted.

Suppose they granted your plan to "cancel the credit card accounts" and "potential fraud source" note on each account. That's pretty much trying to shut down business with their customers. You don't see how they'd interpret that as hostile? Future actors would know how to apply similar techniques if the outcome was in their favor (e.g. Anonymous suddenly produces a large file of cc#'s and threatens bank!) > The only…

When you come across a single credit card number (say, by finding someone's card on the ground), the response by most financial institutions is to invalidate that card and mail them a new one. Why shouldn't the response be the same if you come across a stack of 100 credit cards?

Because shutting down 100 credit cards has more reputation and monetary liability than shutting one down?

You're basically saying "academics can derive your social security number using public information!" And wondering why they don't reissue all of the SSNs...

Re: What Happens When You Send a Zero-Day to a Bank?

#130
post #86

Earlier quoted context omitted.

Suppose they granted your plan to "cancel the credit card accounts" and "potential fraud source" note on each account. That's pretty much trying to shut down business with their customers. You don't see how they'd interpret that as hostile? Future actors would know how to apply similar techniques if the outcome was in their favor (e.g. Anonymous suddenly produces a large file of cc#'s and threatens bank!) > The only…

When you come across a single credit card number (say, by finding someone's card on the ground), the response by most financial institutions is to invalidate that card and mail them a new one. Why shouldn't the response be the same if you come across a stack of 100 credit cards?

The response to invalidate is a choice by the bank, not the person who finds the card. Also, that is a single number. It's suspicious/threatening for a non-trivial amount of cards when the presenter also makes demands.
Post reply on HN